Vulnerability Details CVE-2025-27222
                TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any local server file that is accessible by the TRUfusion user and can also be used to leak cleartext passwords of TRUfusion Enterprise itself.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.112
                        
                    
                    
                        
                            EPSS Ranking 93.2%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 8.6
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2025-27222
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.0.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.1.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.1.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.2.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.3.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.4.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.5.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.5.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.6.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.6.1